ESET Research investigates Gentlemen ransomware gang and its defense-evasion tools
ESET researchers analysed the robust EDR-killing toolset of the ransomware-as-a-service (RaaS) gang Gentlemen. Since the beginning of 2026, Gentlemen has emerged as one of the most active gangs in the ransomware ecosystem. The group distinguishes itself through a mature, operator-maintained set of endpoint detection and response (EDR) killers — tools for disrupting security software. Additionally, unlike most top-tier gangs, Gentlemen does not exhibit a strong US-centric victimology, instead targeting victims across Southeast Asia, South America, and Western Europe. The gang’s targeting includes some otherwise rarely targeted countries like Thailand, Brazil, and France.
“While there have been multiple reports covering Gentlemen in recent months, they have not focused on a detailed analysis of the group’s EDR killers. Thanks to ESET’s continued incident-level visibility, we can provide a uniquely deep view into Gentlemen’s EDR-killer development practices. The internal data leak that Gentlemen suffered in May 2026 gave us more insight into the...
Copyright of this story solely belongs to itvoice.in. To see the full text click HERE